Pass-the-Hash Attacks: Mechanics, Risks and Mitigation
Attackers bypass password verification by reusing cryptographic hashes, rendering complex passphrase policies ineffective against lateral movement.

Pass-the-hash is a technique where an attacker uses a stolen cryptographic hash of a password to authenticate to remote systems. This bypasses the need to decrypt the password. It affects Windows environments using older protocols. Mitigation requires disabling legacy authentication methods and enforcing modern security standards.
The Mechanics of Reusing Credentials
Imagine a building where security guards do not ask for your key, but instead compare the shape of your key against a master mould stored in their office. If you steal that mould, you can open every door without ever possessing the original key. This is the core logic behind pass-the-hash attacks. In technical terms, a hash is a fixed-length string of characters generated by a mathematical function from input data, such as a password. The system stores this hash, not the password itself, for comparison during login.
When a user logs in, the system hashes the entered password and compares it to the stored value. If they match, access is granted. Pass-the-hash exploits this by intercepting the stored hash. The attacker does not need to reverse the hash to find the original password. Instead, they present the captured hash directly to the authentication service. The service accepts it as valid proof of identity. This allows the attacker to move laterally across the network without ever knowing the actual password.
| Aspect | Detail |
|---|---|
| Core Mechanism | Reusing a cryptographic hash instead of the plaintext password |
| Primary Target | Microsoft Windows environments using NTLM or Kerberos |
| Prerequisite | Local or domain administrator access to capture hashes |
| Key Vulnerability | Reliance on legacy authentication protocols that accept hashes |
| Detection Difficulty | High, as authentication logs show successful logins with no decryption errors |
| Primary Mitigation | Disabling legacy protocols and enforcing Credential Guard |
How the Capture Occurs
For this attack to succeed, the attacker must first obtain the hash. This usually happens through initial compromise of a workstation or server. Malware designed for credential dumping searches the memory of the Security Account Manager process on Windows systems. This process holds the Local Security Authority Subsystem Service, which stores the hashes of accounts that have logged into that machine.
The attacker may use legitimate administrative tools or specialised malware to extract these values. Once captured, the hash is copied to the attacker's control machine. The original system remains unaware of the theft because no login attempt has occurred yet. The hash is now a portable credential. It can be used from any machine that has network access to the target system. This detachment means the attacker does not need to stay on the initial compromised host.
Common Forms and Protocols
Not all authentication methods are equally vulnerable. The risk depends heavily on the protocol in use. NTLM is a challenge-response authentication protocol used in Windows networks. It is the most common vector for pass-the-hash because it transmits the hash rather than the password. If an attacker captures an NTLM hash, they can replay it to authenticate to other systems that accept NTLM.
Kerberos is the default authentication protocol for modern Windows domains. It is more complex and generally more secure. However, it is not immune. An attacker with sufficient privileges can request a Ticket Granting Ticket using a stolen hash. This allows them to impersonate the user within the Kerberos ecosystem. The distinction is subtle but significant. While NTLM is often easier to exploit directly, Kerberos abuse requires a deeper understanding of ticket structures and domain policies.
Who Is Affected
This threat primarily targets organisations running Windows-based infrastructure. Any environment where users or services have administrative privileges is at risk. The impact scales with the privilege level of the compromised account. A standard user hash offers limited lateral movement. A domain administrator hash grants access to nearly every system in the domain.
Service accounts are particularly dangerous targets. These accounts often have high privileges and are rarely logged out, keeping their hashes in memory for extended periods. If a service account is compromised, the attacker gains persistent access. This is why least privilege principles are critical. Reducing the number of accounts with administrative rights limits the value of any single captured hash.
What People Usually Get Wrong
A common misconception is that strong passwords prevent pass-the-hash attacks. This is incorrect. The attack bypasses password verification entirely. Whether the password is "password123" or a forty-character passphrase, the hash is the only thing that matters. Increasing password complexity does not add resistance to this specific technique.
Another error is assuming that encryption at rest solves the problem. If the hash is extracted from memory, encryption on the disk is irrelevant. The attacker operates in the active session space. Security teams often focus on protecting the password, but the hash is the actual credential in this context. Shifting focus to hash protection and protocol hygiene is necessary.
See also: Detecting Credential Dumping: Signals, Logs and Blind Spots · How to Implement Red Teaming: A Practical Step-by-Step Framework

Reducing the Risk
Mitigation requires a shift in authentication architecture. The most effective step is disabling legacy authentication protocols. NTLM should be blocked or severely restricted where possible. Modern authentication methods do not transmit hashes in a reusable format. Forcing the use of these modern protocols removes the vector for hash replay.
Microsoft’s Virtualisation-Based Security features, specifically Credential Guard, provide a strong defence. Credential Guard isolates the LSASS process and protects the hashes from being read by malware. Even if an attacker gains administrator access, they cannot easily extract the hashes. This adds a hardware-dependent layer of protection that software-only solutions cannot match.
Regular auditing of administrative rights is also necessary. Identify which accounts have local or domain admin privileges. Remove unnecessary permissions. Monitor for authentication events that use legacy protocols. These logs provide early warning signs of potential abuse. Combining protocol restriction with privilege reduction creates a robust defence.
Related concepts such as remote desktop abuse often accompany this technique, as attackers use stolen hashes to open remote sessions. Understanding scheduled task abuse is also relevant, as attackers may use these tasks to persist after initial access. While threat actors may use various methods, the underlying principle of credential reuse remains constant. This differs from hacktivism, which often relies on public exposure rather than lateral movement. For deeper analysis of network behaviour, reviewing beaconing patterns can help identify the initial compromise that leads to hash theft. Finally, red teaming exercises should include pass-the-hash scenarios to test your defences.
Key takeaways
- Credential theft does not require password decryption to enable lateral movement within a network.
- Legacy authentication protocols remain the primary vector for this attack, even in modern infrastructure.
- Disabling specific legacy protocols is more effective than increasing password complexity for this threat.
Pass-the-hash attacks bypass password strength by reusing cryptographic hashes, making protocol hygiene more critical than complexity. Disable legacy authentication protocols and enforce Credential Guard to eliminate the primary attack vector.
Frequently asked questions
Can antivirus software stop a pass-the-hash attack?
Antivirus may detect the tools used to capture hashes, but it cannot stop the authentication itself. The attack relies on legitimate system functions, so prevention requires architectural changes like disabling legacy protocols.
Does changing a password stop an attacker with a stolen hash?
Yes, resetting the password invalidates the old hash. However, if the attacker has already moved laterally or established persistence, resetting the password does not remove their access. You must also check for active sessions and remove unauthorized access.
Are Linux systems vulnerable to pass-the-hash?
Linux systems typically use different authentication mechanisms that do not store reusable hashes in the same way. While credential theft is possible, the specific pass-the-hash technique is primarily a concern for Windows environments using NTLM or Kerberos.
How do I know if my network is being targeted?
Look for successful authentication events using legacy protocols from unusual source machines. Monitor for lateral movement patterns where a user account accesses multiple servers in a short time. These indicators suggest credential reuse.
How this guide was produced: written by the Malware Brief editorial team with AI assistance, checked against the public references listed below, and reviewed when the facts change. See our editorial policy or report an error.



